Joomla! Discussion Forums



It is currently Wed Nov 25, 2009 3:54 pm (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 7 posts ] 
Author Message
Posted: Fri Oct 30, 2009 12:31 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Thu Oct 29, 2009 11:19 am
Posts: 4
Hello All,

My site has both a public and a private area, meaning that the public area should work with http and the private area with https, but it doesn't. The content of the private area is for registered users only , and the security in the login is very important.

The apache server has been configured to work like this (i've check it several times), which means that the problem resides in the joomla configuration, more precisely in the $mosConfig_live_site variable.

If the value of the $mosConfig_live_site variable is www.mysite.com the site became crazy...
if the value is http://www.mysite.com all the site works using http, and the security of the private area is lost...
if the value is https://www.mysite.com I can access to the site using http (for the first time) but once I select any item, I am again accessing via https and getting problems with the certificate all the time...

The solution would be to switch between http and https as became necessary... I have tried something similiar to the solutions explained in http://forum.joomla.org/viewtopic.php?f=267&t=111332&hilit=https+access and http://forum.joomla.org/viewtopic.php?f=267&t=118767&hilit=ssl+https but it doesn't work for me... maybe there is something i'm missing in that sense.


Any idea about how to solve this problem? All the ideas will be welcome.


P.D: The version of Joomla I'm using is 1.0.11

Thanks in advance.

Cheers,

Cristina


Top
  E-mail  
 
Posted: Fri Oct 30, 2009 9:27 pm 
User avatar
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Mon Mar 20, 2006 1:56 am
Posts: 3703
Location: The Girly Side of Joomla in Sussex
cristinal wrote:
P.D: The version of Joomla I'm using is 1.0.11


sort out this security risk before you get involved in anything else

_________________
HU2HY - GIGO - Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and just deleted
http://community.joomla.org/ Connect Administrator
Avez-vous lu les instructions ? Avez-vous recherché ?


Top
   
 
Posted: Sat Oct 31, 2009 12:28 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Thu Aug 25, 2005 3:29 pm
Posts: 347
Location: Adelaide, South Australia
cristinal wrote:
The version of Joomla I'm using is 1.0.11
Yes, you have posted in the right section. You definitely have a Security problem, that version is way way past its Use-By-Date.

Joomla! 1.0.11 came out on Monday 28th August 2006 !!! That versions Use-By-Date was defined with the release of 1.0.12:
"Joomla! 1.0.12 [ Sunfire ] is available as of Monday the 25th of December 2006 1:00 UTC "

If you cant see the way clear to move up into the 1.5 world then at the very least install a copy of Joomla! 1.0.15 which was the last release for the Joomla! 1.0 series. At least that will bring your site up to what was safe back on Thursday, 21 February 2008.

_________________
Cheers, Ian
"Always remember. Love is the purest feeling, the wisest thought and the strongest reason. Always!"
by Sea-Life
Do Not PM me looking for Help! Un-requested Help PM's will be Deleted Unread, and your ID added to my Ignore List


Top
   
 
Posted: Mon Nov 02, 2009 8:14 am 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Thu Oct 29, 2009 11:19 am
Posts: 4
I'm aware that the problem were solved with the following versions... but right now I can't take the risk of upgrading the version because I don't have enough time these days.

I would appreciate an alternative solution...

Thanks you.


Top
  E-mail  
 
Posted: Mon Nov 02, 2009 5:06 pm 
User avatar
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Mon Mar 20, 2006 1:56 am
Posts: 3703
Location: The Girly Side of Joomla in Sussex
cristinal wrote:
because I don't have enough time these days.
do you have 15 minutes?
Quote:
I would appreciate an alternative solution...Thanks you.

remove your site from the internet and go find something else to do, like play with PSP or something.

if you refuse to upgrade to the latest version then there is no point calling you a website administrator and you probably dont have the time to read this http://docs.joomla.org/Top_10_Stupidest ... tor_Tricks

_________________
HU2HY - GIGO - Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and just deleted
http://community.joomla.org/ Connect Administrator
Avez-vous lu les instructions ? Avez-vous recherché ?


Top
   
 
Posted: Tue Nov 03, 2009 8:57 am 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Thu Oct 29, 2009 11:19 am
Posts: 4
I think that you have misunderstood my response... I'm not refusing to upgrade the joomla version... it is just that I'm not the Website Administrator, this is not my job... and something that takes 15 minutes to a Website Administrator, would take me ages.

We will upgrade the version in the future, but right now the migration is a risk that we can't take due to the amoung of things that depends on that... that is why I was trying to find an alternative solution...

What is your excuse for giving such rude response?


Top
  E-mail  
 
Posted: Tue Nov 03, 2009 11:57 am 
User avatar
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Mon Mar 20, 2006 1:56 am
Posts: 3703
Location: The Girly Side of Joomla in Sussex
cristinal wrote:
it is just that I'm not the Website Administrator, this is not my job

then who is the website administrator? they should be dealing with the site, show them the link provided. and get them to sort out out the issues with the guidance of the documentaiotn and these forums

Quote:
We will upgrade the version in the future,
upgrade today. to the latest 1.0.15 version

Quote:
What is your excuse for giving such rude response?
there was no rudeness in that post just straight facts. you asked for an alternative.

_________________
HU2HY - GIGO - Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and just deleted
http://community.joomla.org/ Connect Administrator
Avez-vous lu les instructions ? Avez-vous recherché ?


Top
   
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

Quick reply

 



Who is online

Users browsing this forum: folo9999 and 22 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group